fix: pin GitHub Actions to SHA hashes #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🔒 Security: Pin GitHub Actions to SHA hashes
This PR pins GitHub Actions to their SHA hashes to improve security by preventing potential supply chain attacks through tag mutation.
Task: DX-1985
One-Pager: Automatic SHA Pinner One-Pager
📊 Summary
📝 Changes Made
.github/workflows/ci.yamlcodecov/codecov-action@v3.1.1→codecov/codecov-action@d9f34f8cd5cb3b3eb79b3e4b5dae3a16df499a70xresloader/upload-to-github-release@v1.3.9→xresloader/upload-to-github-release@a11a070bfe789a1d5e539e4f511fd31ce685aeb3.github/workflows/helmrelease.yamlazure/setup-helm@v3.4→azure/setup-helm@f382f75448129b3be48f8121b9857be18d815a82helm/chart-releaser-action@v1.4.1→helm/chart-releaser-action@98bccfd32b0f76149d188912ac8e45ddd3f8695f🔍 Why this change?
Pinning GitHub Actions to SHA hashes instead of tags provides:
🧪 Testing
❓ Questions?
If you have any questions about this change, feel free to ask the dev-ex team in #notify-dev-ex.
📚 References
🤖 This PR was automatically generated by the SHA Pinner Audit tool.